Re: [RFC][DISCUSSION] Improve uniqid() uniqueness
| From: | Kazuo Oishi | Date: | Tue, 13 Sep 2016 06:23:47 +0000 |
| Subject: | Re: [RFC][DISCUSSION] Improve uniqid() uniqueness | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-95973@lists.php.net to get a copy of this message | ||
Hi,
>> The uniqid() manual explicitly say,
>>
>> - default value of more_entropy is false
>>
>> - the returned string will be 13 characters long. If more_entropy is
>> TRUE, it will be 23 characters.
>>
>> - if more_entropy is set to TRUE, uniqid() will add additional entropy
>> (using the combined linear congruential generator) at the end of the
>> return value
>>
>> http://php.net/manual/en/function.uniqid.php
....
> It's legacy design.
>
> php_combined_lcg() must not be used, especially functions like
> uniqid(). i.e. It's supposed to generate unique ID based on time, but
> php_combined_lcg() generates pseudo random from current time.
>
> It's more than obvious it's legacy and obsolete today.
I agree that uniqid() is legacy design API.
And,
> Current implementation is good enough for most cases, but it can be better.
I agree this legacy design API works good enough for most cases.
So, I think it should not be changed in BC break way.
--
Kazuo Oishi